Threat Actors

Application Security
REVSTEALER Modules Disable Windows Defender to Deploy Miner
Elastic Security Labs found four REVSTEALER persistence modules that remain after the stealer deletes itself, disabling Defender to run a crypto miner.
CVE Vulnerability Alerts
Russia-Aligned UAC-0099 Embeds Nuclear Weapon Text to Evade AI Tools
Russian threat actor UAC-0099 deployed GuardBreaker technique, inserting safety-sensitive phrases into malware to trip AI security analysis mechanisms.
Application Security
360 Attacks Target Langflow and Rails Flaws Within 72 Hours
VulnCheck recorded 360 exploitation attempts targeting CVE-2026-0768 in Langflow and Rails KindaRails2Shell CVE-2026-66066 within 72 hours of disclosure.
Cybersecurity
Five Venezuelan Nationals Plead Guilty to Kansas ATM Jackpotting
Five Venezuelan nationals pleaded guilty to ATM jackpotting conspiracy following December 2025 arrests for Tren de Aragua malware operations in Kansas.
Application Security
JFrog Artifactory CVE-2026-82329 Exploited Days After Disclosure
WatchTowr researchers observed attackers exploiting CVE-2026-82329 to mint admin tokens on JFrog Artifactory instances days after August 28 disclosure.
CVE Vulnerability Alerts
TerminalFix Campaign Uses Reverse Tunnels in ClickFix-Style Attacks
TerminalFix deploys multistage PowerShell attacks incorporating reverse tunnels into victim networks, using ClickFix social engineering to trick users.
Cybersecurity
Gunra Ransomware Exploits Fortinet and Schneider Flaws for MFA Bypass
U.S. and South Korean intelligence agencies warn Gunra ransomware exploits Fortinet firewall flaws alongside a previously undocumented MFA bypass technique.
Cybersecurity
Sandworm Fake Job Interview Campaign Targets Ukrainian IT Workers
CERT-UA attributes a Sandworm-linked UAC-0145 social engineering campaign using fake job interviews and trojanized WireGuard VPN clients against Ukraine.
Cybersecurity
Kimwolf v7 Android Botnet Evades DDoS Mitigation Using HTTP/2 C2
Palo Alto Unit 42 documents Kimwolf v7 using HTTP/2 C2 to mimic legitimate browsing, evade DDoS detection, and expand across Android and IoT devices worldwide.
Cybersecurity
Head Mare Breaches TrueConf Servers, Trojanizes Client Installers
Head Mare hacktivists exploited TrueConf servers and replaced client installers with backdoored versions carrying PhantomCore and PhantomGraph backdoors.